A CISO gets a board mandate to "prepare for the quantum threat" and discovers, a few weeks into the project, that nobody in the organization has a complete inventory of where encryption is actually used — which systems, which algorithms, which vendor libraries nobody has touched in a decade. That discovery, not a breakthrough in a physics lab, is the actual quantum story most organizations are living through right now.

Two separate clocks run in parallel and get treated as one. The research clock produced Google's Willow chip in December 2024, a genuine advance in quantum error correction, and IBM has published a public roadmap targeting a fault-tolerant machine it calls Starling by 2029 — a real commitment, but still a bet on a system that does not exist yet, running on a schedule that has slipped before across the industry and could slip again.

The migration clock is not speculative at all. NIST finalized its post-quantum cryptography standards — FIPS 203, 204, and 205 — in August 2024, formalizing algorithms designed to resist attack even from a quantum computer that can break today's public-key encryption. Signal had already moved first, adding a post-quantum extension to its protocol in 2023, ahead of the formal standard, precisely because the risk it addresses — encrypted data harvested today and decrypted years from now once a capable machine exists — does not wait for the hardware to arrive.

That harvest-now-decrypt-later risk is the actual reason security teams face an immediate decision regardless of when, or whether, a code-breaking quantum computer ever gets built: anything encrypted today with vulnerable algorithms is already exposed to a future capability, which makes today the deadline even though the machine itself is still years away at best.

Confusing the two clocks breaks procurement and policy planning in both directions. Organizations that budget for quantum advantage on a product-announcement timeline risk overinvesting in speculative capability, while organizations that dismiss the cryptographic migration as premature because a fault-tolerant machine is still years off are ignoring a standard that is already finalized and already actionable.

Treated soberly, the NIST migration is a genuinely useful forcing function on its own terms: it pushes an organization to inventory where and how it uses encryption at all, an audit most have never done and that has value independent of when IBM's 2029 target actually lands.

The physics can move at whatever pace the physics moves at. The cryptographic migration NIST already finalized does not need to wait for it, and organizations still treating the two as the same decision are the ones most likely to get the sequencing wrong.